CWE-348 · 69 записей
Use of Less Trusted Source
CVE этого класса
69 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2022-31813Proof of concept | mod_proxy X-Forwarded-For dropped by hop-by-hop mechanismapache · http server · CWE-348 | Критическая9,8 | — | 3,5 % | 9 июн. 2022 г. |
40В плане | CVE-2026-48772Эксплойта нет | ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules.client_addr ACLproxysql · proxysql · CWE-348 | Критическая10,0 | — | 0,2 % | 19 июн. 2026 г. |
37Наблюдать | CVE-2026-58122Эксплойта нет | Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofingnesquena · hermes-webui · CWE-348 | Критическая9,3 | — | 0,4 % | 9 июл. 2026 г. |
36Наблюдать | CVE-2026-97404Эксплойта нет | In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header.openstack · zaqar · CWE-348 | Критическая9,2 | — | 0,3 % | 5 дней назад |
36Наблюдать | CVE-2026-16272Эксплойта нет | Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Modulepaytr payment and electronic money institution inc. · paytr virtual pos iframe api (v9x) whmcs module · CWE-348 | Критическая9,1 | — | 0,1 % | 9 сент. 2026 г. |
36Наблюдать | CVE-2026-12249Эксплойта нет | Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-Enrollmentcanonical · ubuntu 20.04 lts · CWE-348 | Критическая9,0 | — | 0,1 % | 22 июн. 2026 г. |
35Наблюдать | CVE-2024-27773Эксплойта нет | Unitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-348: Use of Less Trusted Sourceunitronics · unilogic · CWE-348 | Высокая8,8 | — | 0,4 % | 18 мар. 2024 г. |
34Наблюдать | CVE-2026-43634Эксплойта нет | HestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP Headerhestiacp · hestiacp · CWE-348 | Высокая8,7 | — | 0,4 % | 19 мая 2026 г. |
34Наблюдать | CVE-2026-64619Эксплойта нет | FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headersvastsa · filecodebox · CWE-348 | Высокая8,7 | — | 0,3 % | 20 июл. 2026 г. |
34Наблюдать | CVE-2026-35391Эксплойта нет | Bulwark Webmail getClientIP() trusted client-controlled X-Forwarded-For value, enabling rate limit bypass and audit log forgerybulwarkmail · webmail · CWE-348 | Высокая8,7 | — | 0,2 % | 6 апр. 2026 г. |
33Наблюдать | CVE-2026-100653Эксплойта нет | vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagationvllm-project · vllm · CWE-348 | Высокая8,3 | — | 0,3 % | 3 дня назад |
32Наблюдать | CVE-2021-21374Эксплойта нет | Nimble fails to validate certificates due to insecure httpClient defaultsnim-lang · nim · CWE-348 | Высокая8,1 | — | 1,0 % | 26 мар. 2021 г. |
32Наблюдать | CVE-2026-63770Эксплойта нет | Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypassglanceapp · glance · CWE-348 | Высокая8,2 | — | 0,3 % | 20 июл. 2026 г. |
32Наблюдать | CVE-2025-55292Эксплойта нет | In Meshtastic, an attacker can spoof licensed amateur flag for a nodemeshtastic · meshtastic firmware · CWE-348 | Высокая8,2 | — | 0,1 % | 27 янв. 2026 г. |
30Наблюдать | CVE-2022-2255Эксплойта нет | A vulnerability was found in mod_wsgi.modwsgi · mod wsgi · CWE-348 | Высокая7,5 | — | 0,9 % | 25 авг. 2022 г. |
30Наблюдать | CVE-2024-23105Эксплойта нет | A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allfortinet · fortiportal · CWE-348 | Высокая7,5 | — | 0,4 % | 14 мая 2024 г. |
30Наблюдать | CVE-2026-59999Эксплойта нет | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.openbsd · openssh · CWE-348 | Высокая7,5 | — | 0,2 % | 7 июл. 2026 г. |
30Наблюдать | CVE-2025-69240Эксплойта нет | Header Poisoning in Raytha CMSraytha · raytha · CWE-348 | Высокая7,5 | — | 0,2 % | 16 мар. 2026 г. |
28Наблюдать | CVE-2025-47424Эксплойта нет | Retool (self-hosted) before 3.196.0 allows Host header injection.retool · retool · CWE-348 | Высокая7,1 | — | 0,2 % | 9 мая 2025 г. |
27Наблюдать | CVE-2026-57942Эксплойта нет | LibreTranslate - IP Spoofing via X-Forwarded-For Headerlibretranslate · libretranslate · CWE-348 | Средняя6,9 | — | 0,3 % | 29 июн. 2026 г. |
27Наблюдать | CVE-2025-53522Эксплойта нет | Movable Type contains an issue with use of less trusted source.six apart ltd. · movable type (software edition) · CWE-348 | Средняя6,9 | — | 0,2 % | 20 авг. 2025 г. |
27Наблюдать | CVE-2025-47149Эксплойта нет | The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation.digital arts inc. · i-filter · CWE-348 | Средняя6,9 | — | 0,2 % | 23 мая 2025 г. |
27Наблюдать | CVE-2026-22201Эксплойта нет | wpDiscuz before 7.6.47 - IP Address Spoofing in getIP()gvectors · wpdiscuz · CWE-348 | Средняя6,9 | — | 0,2 % | 13 мар. 2026 г. |
26Наблюдать | CVE-2022-4537Эксплойта нет | Hide My WP Ghost – Security Plugin <= 5.0.18 - IP Address Spoofing to Protection Mechanism Bypasswpplugins · hide my wp ghost · CWE-348 | Средняя6,5 | — | 0,3 % | 8 мая 2023 г. |
26Наблюдать | CVE-2022-4532Эксплойта нет | LOGIN AND REGISTRATION ATTEMPTS LIMIT<= 2.1 - IP Address Spoofing to Protection Mechanism Bypasskrut1 · login and registration attempts limit · CWE-348 | Средняя6,5 | — | 0,2 % | 17 авг. 2024 г. |
- CVE-2022-3181340В плане
mod_proxy X-Forwarded-For dropped by hop-by-hop mechanism
КритическаяCVSS 9,8Proof of conceptEPSS 4 %apache · http server9 июн. 2022 г.
- CVE-2026-4877240В плане
ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules.client_addr ACL
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %proxysql · proxysql19 июн. 2026 г.
- CVE-2026-5812237Наблюдать
Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofing
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %nesquena · hermes-webui9 июл. 2026 г.
- CVE-2026-9740436Наблюдать
In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header.
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %openstack · zaqar5 дней назад
- CVE-2026-1627236Наблюдать
Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %paytr payment and electronic money institution inc. · paytr virtual pos iframe api (v9x) whmcs module9 сент. 2026 г.
- CVE-2026-1224936Наблюдать
Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-Enrollment
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %canonical · ubuntu 20.04 lts22 июн. 2026 г.
- CVE-2024-2777335Наблюдать
Unitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-348: Use of Less Trusted Source
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %unitronics · unilogic18 мар. 2024 г.
- CVE-2026-4363434Наблюдать
HestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP Header
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %hestiacp · hestiacp19 мая 2026 г.
- CVE-2026-6461934Наблюдать
FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %vastsa · filecodebox20 июл. 2026 г.
- CVE-2026-3539134Наблюдать
Bulwark Webmail getClientIP() trusted client-controlled X-Forwarded-For value, enabling rate limit bypass and audit log forgery
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %bulwarkmail · webmail6 апр. 2026 г.
- CVE-2026-10065333Наблюдать
vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %vllm-project · vllm3 дня назад
- CVE-2021-2137432Наблюдать
Nimble fails to validate certificates due to insecure httpClient defaults
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %nim-lang · nim26 мар. 2021 г.
- CVE-2026-6377032Наблюдать
Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %glanceapp · glance20 июл. 2026 г.
- CVE-2025-5529232Наблюдать
In Meshtastic, an attacker can spoof licensed amateur flag for a node
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %meshtastic · meshtastic firmware27 янв. 2026 г.
- CVE-2022-225530Наблюдать
A vulnerability was found in mod_wsgi.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %modwsgi · mod wsgi25 авг. 2022 г.
- CVE-2024-2310530Наблюдать
A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 all
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %fortinet · fortiportal14 мая 2024 г.
- CVE-2026-5999930Наблюдать
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %openbsd · openssh7 июл. 2026 г.
- CVE-2025-6924030Наблюдать
Header Poisoning in Raytha CMS
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %raytha · raytha16 мар. 2026 г.
- CVE-2025-4742428Наблюдать
Retool (self-hosted) before 3.196.0 allows Host header injection.
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %retool · retool9 мая 2025 г.
- CVE-2026-5794227Наблюдать
LibreTranslate - IP Spoofing via X-Forwarded-For Header
СредняяCVSS 6,9Эксплойта нетEPSS 0 %libretranslate · libretranslate29 июн. 2026 г.
- CVE-2025-5352227Наблюдать
Movable Type contains an issue with use of less trusted source.
СредняяCVSS 6,9Эксплойта нетEPSS 0 %six apart ltd. · movable type (software edition)20 авг. 2025 г.
- CVE-2025-4714927Наблюдать
The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation.
СредняяCVSS 6,9Эксплойта нетEPSS 0 %digital arts inc. · i-filter23 мая 2025 г.
- CVE-2026-2220127Наблюдать
wpDiscuz before 7.6.47 - IP Address Spoofing in getIP()
СредняяCVSS 6,9Эксплойта нетEPSS 0 %gvectors · wpdiscuz13 мар. 2026 г.
- CVE-2022-453726Наблюдать
Hide My WP Ghost – Security Plugin <= 5.0.18 - IP Address Spoofing to Protection Mechanism Bypass
СредняяCVSS 6,5Эксплойта нетEPSS 0 %wpplugins · hide my wp ghost8 мая 2023 г.
- CVE-2022-453226Наблюдать
LOGIN AND REGISTRATION ATTEMPTS LIMIT<= 2.1 - IP Address Spoofing to Protection Mechanism Bypass
СредняяCVSS 6,5Эксплойта нетEPSS 0 %krut1 · login and registration attempts limit17 авг. 2024 г.